Framework
Unified shape: control carries the framework-specific identifier
regardless of framework (SOC 2/ISO 27001 control ID, GDPR article,
PCI-DSS requirement, HIPAA section) — always this one field, never
a framework-specific key like article/requirement/section.
frameworkstringrequired
Possible values: [SOC 2, GDPR, PCI-DSS, HIPAA, ISO 27001]
controlstringrequired
Example:
CC6.1Framework
{
"framework": "SOC 2",
"control": "CC6.1"
}